Skip to main content

Michael Polinski CS PhD Prospectus: Reflections on Trusting Numbers: Attacking and Defending Scientific Software

Thursday, September 10, 2026 | 2:00 PM - 5:00 PM CT
Mudd Hall ( formerly Seeley G. Mudd Library), 3514, 2233 Tech Drive, Evanston, IL 60208 map it
Webcast Link (Hybrid)

How vulnerable to input-driven attacks are the large applications used for computational science? Can these attacks be mitigated? Despite growing concerns about the security of scientific software, no work has empirically evaluated its resistance to adversarial input, and efforts to address concerns of correctness in scientific software are not currently applicable to mitigating vulnerabilities. This thesis begins to address these gaps.

 

I apply standard fuzzing and triage tools to demonstrate that large, open-source scientific applications are highly exploitable through their inputs with ready avenues to arbitrary code execution and thus full control over program output. Next, I implement Crucible, a novel grammar-based fuzzer that searches for small input perturbations, or “nudges”, permitting an adversary to steer the numerical results of such applications by orders of magnitude without relying on conventional vulnerabilities.

 

I propose an expansion of the scope of my studies to include additional applications, variants of attack, and bug detection techniques. I further propose assessing the extent to which formal specification and AI-assisted proof construction could help mitigate – or rule out – a subset of these vulnerabilities, such as the discovered numerical “nudging attacks”.

Audience

  • Faculty/Staff
  • Student
  • Post Docs/Docs
  • Graduate Students

Contact

Jensen Smith
Email

Interest

  • Academic (general)

Add Event To My Group

Please sign-in